Логотип exploitDog
bind:CVE-2022-31098
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-31098

Количество 2

Количество 2

nvd логотип

CVE-2022-31098

больше 3 лет назад

Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in the logging of Weave GitOps could allow an authenticated remote attacker to view sensitive cluster configurations, aka KubeConfg, of registered Kubernetes clusters, including the service account tokens in plain text from Weave GitOps's pod logs on the management cluster. An unauthorized remote attacker can also view these sensitive configurations from external log storage if enabled by the management cluster. This vulnerability is due to the client factory dumping cluster configurations and their service account tokens when the cluster manager tries to connect to an API server of a registered cluster, and a connection error occurs. An attacker could exploit this vulnerability by either accessing logs of a pod of Weave GitOps, or from external log storage and obtaining all cluster configurations of registered clusters. A successf

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-xggc-qprg-x6mw

больше 3 лет назад

Weave GitOps leaked cluster credentials into logs on connection errors

CVSS3: 9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-31098

Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in the logging of Weave GitOps could allow an authenticated remote attacker to view sensitive cluster configurations, aka KubeConfg, of registered Kubernetes clusters, including the service account tokens in plain text from Weave GitOps's pod logs on the management cluster. An unauthorized remote attacker can also view these sensitive configurations from external log storage if enabled by the management cluster. This vulnerability is due to the client factory dumping cluster configurations and their service account tokens when the cluster manager tries to connect to an API server of a registered cluster, and a connection error occurs. An attacker could exploit this vulnerability by either accessing logs of a pod of Weave GitOps, or from external log storage and obtaining all cluster configurations of registered clusters. A successf

CVSS3: 9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xggc-qprg-x6mw

Weave GitOps leaked cluster credentials into logs on connection errors

CVSS3: 9
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу